I'm looking to setup autologon/'keep you logged in' for a social website I'm building.
There is a tickbox for the user to enable this feature and I planned to write 3 cookies to there system including 'autologon enabled', 'username encrypted in SHA' and 'password encrypted in SHA'.
The catch is "it appears" if anyone accessed there system they could get the username and password SHA Hashes form the cookies and with a touch of skill use these to logon as the person. This is correct right?
Thinking about it I assume any system that keeps you logged in would have to use cookies like this and therefore is vulnerable to cookie theft. Is this correct?
Finally is there anyway I can implement autologon/keep me logged in - in a secure or more so secure fashion?
thankyou
Note: Facebook seems to do this - as I'm always logged in... I assume they have a secure method? assumption there...